Protecting Cookies with Device Bound Session Credentials

2026-04-09T19:23:43Ze5299e634c270fc0c20b66ba82456711734077e2a6911da3b650622921d22d7f
AndroidAndroid 17Certificate TransparencyChrome 146DBSCDevice Bound Session CredentialsGeminiIPILLM securityLummaC2MTCMerkle Tree CertificatesPLANTS IETF working groupPQCVRPVulnerability Rewards ProgramWindowscookie theftindirect prompt injectioninfostealermacOSpost-quantum cryptographyprompt injectionquantum-safe HTTPSsession hijacking

What happened

This collection of Google Security Blog posts (Mar–Apr 2026) announces multiple defensive and roadmap updates: Device Bound Session Credentials (DBSC) is now publicly available for Windows in Chrome 146 (with macOS coming soon) to proactively prevent cookie/session theft by tying session credentials to a device and making exfiltrated cookies unusable; Google Workspace is adopting continuous mitigations against indirect prompt injection (IPI) targeting LLMs and agentic automation; Google published a VRP (Vulnerability Rewards Program) 2025 year-in-review; Android will begin tests of Post‑Quantm

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
e5299e634c270fc0c20b66ba82456711734077e2a6911da3b650622921d22d7f
Enrichment time
2026-04-09T19:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.